
10.4.1 Establishing the Configuration Task
Before configuring an advanced ACL, familiarize yourself with the applicable environment,
complete the pre-configuration tasks, and obtain the data required for the configuration. This
will help you complete the configuration task quickly and accurately.
Applicable Environment
Advanced ACLs are applied to multiple services and functions, for example, traffic classifiers
and multicast. The AR1200-S processes different types of packets based on advanced ACL rules.
Advanced ACLs can be applied to:
l
All the IPv4 packets at the network layer and upper layers. Advanced ACLs classify IPv4
packets based on information such as source and destination IP addresses, packet priorities,
fragment flags, time ranges, and VPN instances in the packets.
NOTE
An advanced ACL is similar to a basic ACL, but defines more information than a basic ACL.
l
Specified types of packets include GRE packets, ICMP packets, IPinIP packets, OSPF
packets, ICMP packets, UDP packets, and TCP packets. Advanced ACLs classify these
packet types based on different types of information:
–
GRE packets, ICMP packets, IPinIP packets, and OSPF packets are classified based on
information such as source and destination IP addresses, packet priorities, fragment
flags, time ranges, and VPN instances in the packets.
–
ICMP packets are classified based on information such as source and destination IP
addresses, packet priorities, fragment flags, ICMP packet types and codes, time ranges,
and VPN instances in the packets.
–
UDP packets are classified based on information such as source and destination IP
addresses, source and destination port numbers, packet priorities, fragment flags, time
ranges, and VPN instances in the packets.
–
TCP packets are classified based on information such as source and destination IP
addresses, source and destination port numbers, SYN flag types, packet priorities,
fragment flags, time ranges, and VPN instances in the packets.
Pre-configuration Tasks
Before configuring an advanced ACL, complete the following task:
l
Setting link layer protocol parameters for interfaces to ensure that the link layer protocol
status on the interfaces is Up
Data Preparation
To configure an advanced ACL, you need the following data.
No.
Data
1
(Optional) Name of a time range during which ACL rules take effect
2
Number or name of an advanced ACL
3
Protocol type
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
10 ACL Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
195